THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-j5jq-cr68-v2xx (high) — Winter: Authenticated backend users can bypass Users controller permission checks

[GHSA] GHSA-j5jq-cr68-v2xx (high) — Winter: Authenticated backend users can bypass Users controller permission checks

medgithub_advisoriesPublished 2026-08-12

GHSA-j5jq-cr68-v2xx Severity: high CVE: CVE-2026-35445

Winter: Authenticated backend users can bypass Users controller permission checks

### Impact

Affected versions of Winter CMS did not validate the handler name submitted through the form postback mechanism (`_handler` POST field) in the same way as AJAX requests (`X_WINTER_REQUEST_HANDLER` header). The AJAX path validates that handler names

Indicators of compromise

Original source: https://github.com/advisories/GHSA-j5jq-cr68-v2xx